VCasel Filename Trusting Vulnerability
BID:937
Info
VCasel Filename Trusting Vulnerability
| Bugtraq ID: | 937 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 18 2000 12:00AM |
| Updated: | Jan 18 2000 12:00AM |
| Credit: | First posted to Bugtraq by Bob Mare <[email protected]> on January 18, 2000. |
| Vulnerable: |
Computer Power Solutions Visual CASEL 3.5 Computer Power Solutions Visual CASEL 3.0 |
| Not Vulnerable: | |
Discussion
VCasel Filename Trusting Vulnerability
Visual CASEL from Computer Power Solutions is a security product for Novell and Windows NT networks. It (among other things) provides the capability for limiting what a user on a network can execute based on "trusted filenames". Unfortunately, Visual CASEL places all of its trust in the name of the file _only_ instead of the absolute path and filename of the trusted files (that users can execute). Because of this, it is possible to run a malicious file which should not normally be executable if the filename is that of a "trusted file". An example follows (summarized example from xDeath's bugtraq post):
A user copies pong.exe to his home directory and attempts to execute it (and is denied).
The user renames pong.exe to write.exe and executes it.
("write.exe" is a trusted filename, as opposed to C:\windows\write.exe).
Visual CASEL from Computer Power Solutions is a security product for Novell and Windows NT networks. It (among other things) provides the capability for limiting what a user on a network can execute based on "trusted filenames". Unfortunately, Visual CASEL places all of its trust in the name of the file _only_ instead of the absolute path and filename of the trusted files (that users can execute). Because of this, it is possible to run a malicious file which should not normally be executable if the filename is that of a "trusted file". An example follows (summarized example from xDeath's bugtraq post):
A user copies pong.exe to his home directory and attempts to execute it (and is denied).
The user renames pong.exe to write.exe and executes it.
("write.exe" is a trusted filename, as opposed to C:\windows\write.exe).
Exploit / POC
VCasel Filename Trusting Vulnerability
See discussion.
See discussion.
Solution / Fix
VCasel Filename Trusting Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].